BlogsBattle | 19.03.2013 22:31 | ADWCCLEANER:AdwCleaner Logfile: Code:
# AdwCleaner v2.115 - Datei am 19/03/2013 um 22:18:25 erstellt
# Aktualisiert am 17/03/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzer : user - USER-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\user\Downloads\adwcleaner (1).exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
***** [Registrierungsdatenbank] *****
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16521
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v [Version kann nicht ermittelt werden]
*************************
AdwCleaner[S1].txt - [28874 octets] - [19/03/2013 20:01:45]
AdwCleaner[S2].txt - [690 octets] - [19/03/2013 22:18:25]
########## EOF - C:\AdwCleaner[S2].txt - [749 octets] ########## --- --- ---
OTL.exe:OTL Logfile: Code:
OTL logfile created on: 19.03.2013 22:23:32 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\user\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000807 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy
2.97 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 57.88% Memory free
5.96 Gb Paging File | 4.59 Gb Available in Paging File | 76.88% Paging File free
Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.56 Gb Total Space | 57.62 Gb Free Space | 59.06% Space Free | Partition Type: NTFS
Drive F: | 135.23 Gb Total Space | 134.41 Gb Free Space | 99.39% Space Free | Partition Type: NTFS
Computer Name: USER-PC | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.03.19 22:22:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\user\Downloads\OTL (2).exe
PRC - [2013.03.11 01:22:07 | 001,274,320 | ---- | M] (Google Inc.) -- C:\Programme\Google\Chrome\Application\chrome.exe
PRC - [2013.02.11 17:07:06 | 000,223,808 | ---- | M] (blekko) -- C:\ProgramData\File Bulldog Anti-phishing Domain Advisor\filebulldog_antiphishing.exe
PRC - [2013.01.27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\NisSrv.exe
PRC - [2013.01.27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MsMpEng.exe
PRC - [2013.01.27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2013.01.26 07:08:30 | 004,480,768 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\user\AppData\Local\Akamai\netsession_win.exe
PRC - [2012.12.16 12:25:18 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) -- C:\Programme\Sandboxie\SbieSvc.exe
PRC - [2012.11.30 03:55:25 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012.11.29 10:32:16 | 002,086,984 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\Programme\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe
PRC - [2012.11.23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012.07.17 14:49:00 | 001,713,904 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2012.07.17 14:49:00 | 000,194,304 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2012.06.11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) -- C:\Programme\Microsoft\BingBar\7.1.391.0\BBSvc.EXE
PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.06.04 18:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009.06.04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe
========== Modules (No Company Name) ==========
MOD - [2013.03.11 01:22:06 | 000,459,728 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\ppgooglenaclpluginchrome.dll
MOD - [2013.03.11 01:22:05 | 012,662,224 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
MOD - [2013.03.11 01:22:04 | 004,050,896 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\pdf.dll
MOD - [2013.03.11 01:21:18 | 000,596,944 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\libglesv2.dll
MOD - [2013.03.11 01:21:18 | 000,124,368 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\libegl.dll
MOD - [2013.03.11 01:21:16 | 001,552,848 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\ffmpegsumo.dll
========== Services (SafeList) ==========
SRV - [2013.03.19 16:29:25 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.02.28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.02.27 13:43:04 | 004,539,712 | ---- | M] () [Auto | Running] -- C:/Program Files/Common Files/Akamai/netsession_win_ce5ba24.dll -- (Akamai)
SRV - [2013.01.27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013.01.27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.12.16 12:25:18 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2012.09.12 15:58:46 | 001,512,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2012.07.17 14:49:00 | 001,713,904 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2012.06.11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Programme\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012.06.11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Programme\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2011.04.18 00:28:01 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.06.04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2003.07.28 11:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (VBoxNetFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (Synth3dVsc)
DRV - File not found [File_System | On_Demand | Stopped] -- -- (StarOpen)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\user\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (akuzpcec)
DRV - [2013.01.20 15:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012.12.21 13:54:00 | 000,014,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv)
DRV - [2012.12.21 13:53:58 | 000,009,160 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2012.12.16 12:25:16 | 000,157,776 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2012.11.13 21:53:00 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Programme\Razer\Razer Game Booster\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - [2012.09.28 20:17:38 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012.09.28 20:16:08 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011.05.18 07:09:04 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2011.05.13 17:57:42 | 000,025,656 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hpdskflt.sys -- (hpdskflt)
DRV - [2011.05.13 17:57:20 | 000,035,896 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2011.04.21 14:14:45 | 000,004,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nocashio.sys -- (nocashio)
DRV - [2010.11.20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010.11.20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.07.22 22:01:00 | 009,791,072 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.07.20 03:39:20 | 000,116,136 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\jmcr.sys -- (JMCR)
DRV - [2009.06.25 23:55:12 | 000,066,080 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2009.03.18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory =
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = MSN Schweiz : Hotmail, Outlook, Skype download, Unterhaltung, Nachrichten, Sport, Lifestyle, Auto und mehr bei MSN CH
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-ch
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 61 15 EB A8 42 FC CB 01 [binary data]
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?FORM=UP21DF&PC=UP21&dt=031913&q={searchTerms}&src=IE-SearchBox
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\SearchScopes\{A24B23B3-6F36-4D6A-B21E-45D059F25D50}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYCH&apn_uid=2180B476-059B-4960-9567-F78D405B7FD8&apn_sauid=B98193CC-0BA5-4D6D-9988-1868E1C4BF38
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "DVDVideoSoftTB Customized Web Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.claro-search.com/?affID=114508&tt=4212_3&babsrc=HP_clro&mntrId=ec3baacd000000000000002100a83bd4"
FF - prefs.js..extensions.enabledAddons: helperbar@helperbar.com:1.0
FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.1.3
FF - prefs.js..extensions.enabledAddons: ffox@bandoo.com:5.1
FF - prefs.js..extensions.enabledAddons: ffxtlbr@Facemoods.com:1.2.1
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.4
FF - prefs.js..extensions.enabledAddons: {51a86bb3-6602-4c85-92a5-130ee4864f13}:3.6.0.10
FF - prefs.js..extensions.enabledAddons: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.5.0.12
FF - prefs.js..extensions.enabledAddons: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledAddons: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledAddons: {64ead72b-ffd4-4e01-aa3a-4c71665d73e4}:3.9.0.3
FF - prefs.js..extensions.enabledAddons: {90b49673-5506-483e-b92b-ca0265bd9ca8}:3.9.0.3
FF - prefs.js..extensions.enabledAddons: {40c3cc16-7269-4b32-9531-17f2950fb06f}:3.9.0.3
FF - prefs.js..extensions.enabledAddons: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.96
FF - prefs.js..extensions.enabledAddons: {3e9a3920-1b27-11da-8cd6-0800200c9a66}:3.6.3
FF - prefs.js..extensions.enabledAddons: {26647ca4-a2a7-4eac-8a72-761aa9141de7}:3.10.0.1
FF - prefs.js..extensions.enabledAddons: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.10.0.1
FF - prefs.js..extensions.enabledAddons: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}:2.0
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..browser.startup.homepage: "hxxp://home.sweetim.com/?crg=3.1010000.10001&barid={F1294482-9607-4144-92A5-7226087A4A2A}"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Softonic)"
FF - prefs.js..browser.startup.homepage: "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=13&cc="
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: F:\Program Files\AdobeReader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@eximion.com/KalydoPlayer: C:\Users\user\AppData\Roaming\Kalydo\KalydoPlayer\bin\npkalydo.dll (Eximion B.V.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\user\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\user\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\crossriderapp498@crossrider.com: C:\Users\user\AppData\Local\RewardsArcade\498\Firefox [2012.03.25 16:14:33 | 000,000,000 | ---D | M]
[2011.12.03 19:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\mozilla\Extensions
[2013.03.19 19:54:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\cev9a7zx.default\extensions
[2013.01.04 16:52:34 | 000,000,000 | ---D | M] (Wajam) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\cev9a7zx.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}
[2013.02.24 22:06:37 | 000,000,000 | ---D | M] (Claro Toolbar) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\cev9a7zx.default\extensions\ffxtlbr@claro.com
[2012.10.24 20:11:48 | 000,054,399 | ---- | M] () (No name found) -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\extensions\pricepeep@getpricepeep.com.xpi
[2012.10.13 18:27:00 | 000,037,914 | ---- | M] () (No name found) -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
[2013.02.23 19:21:04 | 000,002,308 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\askcom.xml
[2012.10.14 00:00:11 | 000,002,546 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\browsemngr.xml
[2013.02.24 22:06:54 | 000,001,300 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\claro.xml
[2011.07.24 14:30:04 | 000,000,931 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\conduit.xml
[2013.02.01 17:02:10 | 000,001,294 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\delta.xml
[2012.03.18 17:30:30 | 000,002,412 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\Linkury Smartbar Search.xml
[2011.07.23 20:05:08 | 000,002,501 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\SearchResults.xml
[2011.12.03 19:06:09 | 000,002,519 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\Search_Results.xml
[2012.04.26 16:25:51 | 000,002,060 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\softonic.xml
[2012.09.27 19:47:52 | 000,003,993 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\sweetim.xml
O1 HOSTS File: ([2013.03.19 20:23:09 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (File Bulldog Toolbar) - {1393c215-0520-410e-ab29-3badab478ec4} - C:\Programme\filebulldogtb\filebulldogDx.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programme\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (File Bulldog Toolbar) - {1393c215-0520-410e-ab29-3badab478ec4} - C:\Programme\filebulldogtb\filebulldogDx.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [EaseUS EPM tray] C:\Programme\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [File Bulldog Anti-phishing Domain Advisor] C:\ProgramData\File Bulldog Anti-phishing Domain Advisor\filebulldog_antiphishing.exe (blekko)
O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000..\Run: [Akamai NetSession Interface] C:\Users\user\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - F:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.17.2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 85.119.136.140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77D5C26F-38A8-48EE-AA8F-CB479292E4BA}: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 85.119.136.140
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.19 21:39:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013.03.19 21:39:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013.03.19 21:39:29 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2013.03.19 21:27:40 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Skype
[2013.03.19 20:28:25 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.03.19 20:23:15 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.03.19 20:21:00 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\temp
[2013.03.19 20:11:02 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.03.19 20:11:02 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.03.19 20:11:02 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.03.19 20:10:58 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013.03.19 20:10:52 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.03.19 20:10:37 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.03.17 20:56:13 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\SumRando
[2013.03.17 20:56:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SumRando
[2013.03.17 20:55:05 | 000,000,000 | ---D | C] -- C:\Program Files\SumRando
[2013.03.17 20:50:20 | 000,000,000 | ---D | C] -- C:\toolbarImages
[2013.03.17 19:13:41 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\AVG
[2013.03.17 19:12:31 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG
[2013.03.17 19:12:28 | 000,000,000 | -HSD | C] -- C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
[2013.03.17 16:34:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013.03.11 20:34:48 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\DealPly
[2013.03.10 22:40:39 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\AVG2013
[2013.03.10 22:39:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013.03.10 22:39:24 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2013.03.10 22:39:24 | 000,000,000 | ---D | C] -- C:\$AVG
[2013.03.10 22:38:44 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2013.03.10 22:36:14 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\MFAData
[2013.03.10 22:36:14 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2013.03.10 22:36:14 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Avg2013
[2013.03.10 20:29:28 | 000,000,000 | ---D | C] -- C:\Windows\Repair
[2013.03.10 19:46:30 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2013.03.07 19:14:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Logs
[2013.03.05 22:33:18 | 000,000,000 | ---D | C] -- C:\ProgramData\filebulldogtb
[2013.03.04 21:17:08 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\.minecraft
[2013.03.01 19:09:53 | 000,000,000 | ---D | C] -- C:\Windows\System32\Neuer Ordner
[2013.02.28 19:20:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.2
[2013.02.28 19:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\Cheat Engine 6.2
[2013.02.28 19:19:45 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\filebulldogtb
[2013.02.28 19:19:44 | 000,000,000 | ---D | C] -- C:\ProgramData\File Bulldog Anti-phishing Domain Advisor
[2013.02.28 19:19:26 | 000,000,000 | ---D | C] -- C:\Program Files\filebulldogtb
[2013.02.28 19:14:47 | 000,000,000 | ---D | C] -- C:\Program Files\DragonCityBot
[2013.02.27 19:15:28 | 000,000,000 | ---D | C] -- C:\Windows\de
[2013.02.27 19:06:54 | 000,000,000 | R--D | C] -- C:\Users\user\SkyDrive
[2013.02.27 19:06:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SkyDrive
[2013.02.27 19:06:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft SkyDrive
[2013.02.27 14:05:44 | 000,000,000 | ---D | C] -- C:\Program Files\alaplaya
[2013.02.27 13:42:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Akamai
[2013.02.26 22:13:08 | 000,000,000 | ---D | C] -- C:\Users\user\tre
[2013.02.24 00:45:25 | 000,000,000 | ---D | C] -- C:\Program Files\RAR Password Unlocker
[2013.02.21 23:46:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Systweak
[2013.02.21 19:47:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
[2013.02.21 19:06:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
[2013.02.21 19:06:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\TechSmith Shared
[2013.02.21 19:05:21 | 000,000,000 | ---D | C] -- C:\Program Files\TechSmith
[2013.02.21 00:57:23 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Solveig Multimedia
[2013.02.21 00:55:30 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\HyperCam3
[2013.02.19 22:08:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2013.02.19 01:04:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Software
[16 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.03.19 22:29:07 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.19 22:25:41 | 000,020,704 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.19 22:25:41 | 000,020,704 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.19 22:19:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.19 22:19:26 | 2390,114,304 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.19 21:43:50 | 000,289,472 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.03.19 21:39:33 | 000,002,505 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2013.03.19 21:36:01 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3523815195-3484323984-766912794-1000UA.job
[2013.03.19 21:36:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3523815195-3484323984-766912794-1000Core.job
[2013.03.19 21:23:47 | 000,362,029 | ---- | M] () -- C:\Windows\System32\sqlite3.dll
[2013.03.19 20:23:09 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.03.18 22:26:07 | 050,069,504 | ---- | M] () -- C:\Windows\System32\RBK9DEC.bak
[2013.03.18 22:26:07 | 018,087,936 | ---- | M] () -- C:\Windows\System32\RBK9DEF.bak
[2013.03.18 22:26:07 | 000,524,288 | ---- | M] () -- C:\Windows\System32\RBK9DF4.bak
[2013.03.18 22:26:07 | 000,262,144 | -HS- | M] () -- C:\Windows\System32\RBK9E04.bak
[2013.03.18 22:26:07 | 000,262,144 | -HS- | M] () -- C:\Windows\System32\RBK9DFF.bak
[2013.03.18 22:26:07 | 000,262,144 | ---- | M] () -- C:\Windows\System32\RBK9DFC.bak
[2013.03.18 22:26:07 | 000,262,144 | ---- | M] () -- C:\Windows\System32\RBK9DF7.bak
[2013.03.18 22:25:48 | 004,718,592 | -H-- | M] () -- C:\Windows\System32\RBK9E0C.bak
[2013.03.18 22:25:48 | 004,194,304 | -HS- | M] () -- C:\Windows\System32\RBK9E07.bak
[2013.03.18 17:22:01 | 001,622,772 | ---- | M] () -- C:\Users\user\Desktop\x7.rar
[2013.03.18 17:21:48 | 000,648,112 | ---- | M] () -- C:\Users\user\Desktop\x7 Loader v1.0.0.zip
[2013.03.17 20:11:16 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2013.03.09 18:42:10 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for user.job
[2013.03.03 03:24:33 | 001,959,131 | ---- | M] () -- C:\main.wma
[2013.03.03 02:48:43 | 000,062,183 | ---- | M] () -- C:\xluiscolx.gif
[2013.02.27 13:59:41 | 000,008,627 | ---- | M] () -- C:\Windows\System32\PAV_FOG.OPC
[2013.02.22 00:38:37 | 000,007,602 | ---- | M] () -- C:\Users\user\AppData\Local\resmon.resmoncfg
[2013.02.21 00:57:24 | 000,005,632 | ---- | M] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.02.21 00:21:36 | 000,094,779 | ---- | M] () -- C:\Users\user\Documents\Unbenannt.wma
[2013.02.20 13:51:22 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013.02.20 13:28:09 | 003,124,964 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.02.20 13:28:09 | 001,385,526 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.02.20 13:28:09 | 000,924,562 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.02.20 13:28:09 | 000,820,910 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.02.18 01:12:03 | 000,001,506 | ---- | M] () -- C:\Windows\Sandboxie.ini
[16 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.03.19 21:43:24 | 000,289,472 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.03.19 21:39:33 | 000,002,505 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2013.03.19 21:23:47 | 000,362,029 | ---- | C] () -- C:\Windows\System32\sqlite3.dll
[2013.03.19 20:11:02 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.03.19 20:11:02 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.03.19 20:11:02 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.03.19 20:11:02 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.03.19 20:11:02 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.03.17 21:56:16 | 001,622,772 | ---- | C] () -- C:\Users\user\Desktop\x7.rar
[2013.03.17 21:56:13 | 000,648,112 | ---- | C] () -- C:\Users\user\Desktop\x7 Loader v1.0.0.zip
[2013.03.17 20:11:16 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2013.03.03 22:22:31 | 000,062,183 | ---- | C] () -- C:\xluiscolx.gif
[2013.03.03 22:22:30 | 001,959,131 | ---- | C] () -- C:\main.wma
[2013.02.27 19:14:40 | 000,001,251 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2013.02.27 19:13:55 | 000,001,320 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2013.02.27 19:06:54 | 000,002,172 | ---- | C] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
[2013.02.21 00:21:36 | 000,094,779 | ---- | C] () -- C:\Users\user\Documents\Unbenannt.wma
[2013.02.19 23:23:28 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013.02.19 23:22:46 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013.02.19 22:09:06 | 000,001,912 | ---- | C] () -- C:\Windows\epplauncher.mif
[2013.02.19 22:08:21 | 000,002,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013.02.03 23:07:15 | 002,468,520 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2013.02.03 23:07:15 | 000,087,112 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2013.02.03 23:07:15 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2013.02.03 23:07:15 | 000,014,920 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2013.02.03 23:07:15 | 000,009,160 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2012.08.23 17:42:56 | 000,828,671 | ---- | C] () -- C:\Users\user\AppData\Local\Tempmusic.ogg
[2012.08.22 13:45:57 | 000,001,506 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2012.03.05 18:32:59 | 000,000,833 | ---- | C] () -- C:\Users\user\.recently-used.xbel
[2012.02.26 17:41:54 | 000,000,023 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011.09.15 01:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin
[2011.08.22 20:31:19 | 000,005,632 | ---- | C] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.18 17:10:31 | 000,001,087 | ---- | C] () -- C:\Users\user\Dokumente - Verknüpfung.lnk
[2011.07.08 19:48:57 | 000,273,148 | ---- | C] () -- C:\Windows\Bergbau0.8.exe
[2011.06.20 23:54:54 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.06.20 23:52:24 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.04.26 21:10:37 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.04.21 14:14:45 | 000,004,096 | ---- | C] () -- C:\Windows\System32\drivers\nocashio.sys
[2011.04.15 16:36:25 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2011.04.15 16:10:42 | 000,007,602 | ---- | C] () -- C:\Users\user\AppData\Local\resmon.resmoncfg
[2011.04.15 15:31:09 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.03.17 16:28:21 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\AVG2013
[2013.02.22 11:31:53 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Bandoo
[2013.02.13 10:57:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\dll-files.com
[2013.02.22 11:28:42 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Systweak
[2013.03.13 18:38:05 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\.minecraft
[2012.09.06 17:07:52 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\.Nitrous
[2011.09.08 21:06:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ACASystems
[2012.09.22 17:30:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Aeria Games & Entertainment
[2012.11.02 22:43:41 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ArmA II Launcher
[2012.11.12 21:04:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Audacity
[2013.01.30 23:00:47 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Auslogics
[2013.03.17 19:13:41 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\AVG
[2013.03.10 22:40:39 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\AVG2013
[2011.07.25 20:03:48 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\avidemux
[2013.01.27 16:17:16 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Azureus
[2012.03.22 18:15:59 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Babylon
[2011.06.22 20:25:29 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Bandoo
[2012.08.12 13:47:12 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\bin
[2013.02.27 13:35:44 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\BitTorrent
[2011.04.16 23:54:09 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Canneverbe Limited
[2011.09.03 12:33:27 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Charles
[2013.01.27 16:17:16 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DAEMON Tools Lite
[2011.09.17 17:05:11 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DAEMON Tools Pro
[2013.03.11 20:34:48 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DealPly
[2012.12.24 00:35:11 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\dll-files.com
[2011.08.13 17:34:38 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DVDVideoSoft
[2011.08.13 17:32:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.04.15 15:27:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ESET
[2012.03.22 18:18:37 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\eType
[2011.04.26 21:14:10 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FireShot
[2011.07.22 20:08:03 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FOG Downloader
[2011.05.15 22:05:18 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\GetRightToGo
[2012.03.05 18:34:52 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\gtk-2.0
[2012.01.10 21:28:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Kalydo
[2013.02.02 14:58:05 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\MessengerDiscovery 2
[2011.08.01 18:06:23 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\minecraft
[2011.07.25 22:44:35 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Minecraft Server 1.5
[2013.01.11 23:21:01 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\MTE
[2013.02.25 22:21:51 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Notepad++
[2013.01.15 16:43:45 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenCandy
[2012.03.22 18:22:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PerformerSoft
[2012.11.02 22:37:52 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Play withSIX
[2011.04.17 22:48:05 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ProtectDISC
[2011.07.01 22:42:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\resources
[2011.07.01 22:42:17 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\saves
[2013.02.21 01:04:55 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Solveig Multimedia
[2013.02.27 13:35:41 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\stats
[2013.03.19 19:55:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\systweak
[2012.10.22 16:46:18 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TechSmith
[2012.08.12 13:47:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TS3Client
[2013.03.10 22:39:53 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TuneUp Software
[2013.01.04 16:53:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TuneUpMedia
[2013.02.27 13:35:41 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\uTorrent
[2011.07.19 21:26:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012.08.20 18:17:39 | 000,000,000 | ---D | M](C:\Windows\System32\????sers) -- C:\Windows\System32\༸sers
[2012.08.20 18:17:39 | 000,000,000 | ---D | C](C:\Windows\System32\????sers) -- C:\Windows\System32\༸sers
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:373E1720
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:07BF512B
< End of report > --- --- ---
ADWCCLEANER:AdwCleaner Logfile: Code:
# AdwCleaner v2.115 - Datei am 19/03/2013 um 22:18:25 erstellt
# Aktualisiert am 17/03/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzer : user - USER-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\user\Downloads\adwcleaner (1).exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
***** [Registrierungsdatenbank] *****
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16521
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v [Version kann nicht ermittelt werden]
*************************
AdwCleaner[S1].txt - [28874 octets] - [19/03/2013 20:01:45]
AdwCleaner[S2].txt - [690 octets] - [19/03/2013 22:18:25]
########## EOF - C:\AdwCleaner[S2].txt - [749 octets] ########## --- --- ---
OTL.exe:OTL Logfile: Code:
OTL logfile created on: 19.03.2013 22:23:32 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\user\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000807 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy
2.97 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 57.88% Memory free
5.96 Gb Paging File | 4.59 Gb Available in Paging File | 76.88% Paging File free
Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.56 Gb Total Space | 57.62 Gb Free Space | 59.06% Space Free | Partition Type: NTFS
Drive F: | 135.23 Gb Total Space | 134.41 Gb Free Space | 99.39% Space Free | Partition Type: NTFS
Computer Name: USER-PC | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.03.19 22:22:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\user\Downloads\OTL (2).exe
PRC - [2013.03.11 01:22:07 | 001,274,320 | ---- | M] (Google Inc.) -- C:\Programme\Google\Chrome\Application\chrome.exe
PRC - [2013.02.11 17:07:06 | 000,223,808 | ---- | M] (blekko) -- C:\ProgramData\File Bulldog Anti-phishing Domain Advisor\filebulldog_antiphishing.exe
PRC - [2013.01.27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\NisSrv.exe
PRC - [2013.01.27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MsMpEng.exe
PRC - [2013.01.27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2013.01.26 07:08:30 | 004,480,768 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\user\AppData\Local\Akamai\netsession_win.exe
PRC - [2012.12.16 12:25:18 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) -- C:\Programme\Sandboxie\SbieSvc.exe
PRC - [2012.11.30 03:55:25 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012.11.29 10:32:16 | 002,086,984 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\Programme\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe
PRC - [2012.11.23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012.07.17 14:49:00 | 001,713,904 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2012.07.17 14:49:00 | 000,194,304 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2012.06.11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) -- C:\Programme\Microsoft\BingBar\7.1.391.0\BBSvc.EXE
PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.06.04 18:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009.06.04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe
========== Modules (No Company Name) ==========
MOD - [2013.03.11 01:22:06 | 000,459,728 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\ppgooglenaclpluginchrome.dll
MOD - [2013.03.11 01:22:05 | 012,662,224 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
MOD - [2013.03.11 01:22:04 | 004,050,896 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\pdf.dll
MOD - [2013.03.11 01:21:18 | 000,596,944 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\libglesv2.dll
MOD - [2013.03.11 01:21:18 | 000,124,368 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\libegl.dll
MOD - [2013.03.11 01:21:16 | 001,552,848 | ---- | M] () -- C:\Programme\Google\Chrome\Application\25.0.1364.172\ffmpegsumo.dll
========== Services (SafeList) ==========
SRV - [2013.03.19 16:29:25 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.02.28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.02.27 13:43:04 | 004,539,712 | ---- | M] () [Auto | Running] -- C:/Program Files/Common Files/Akamai/netsession_win_ce5ba24.dll -- (Akamai)
SRV - [2013.01.27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013.01.27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.12.16 12:25:18 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2012.09.12 15:58:46 | 001,512,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2012.07.17 14:49:00 | 001,713,904 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2012.06.11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Programme\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012.06.11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Programme\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2011.04.18 00:28:01 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.06.04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2003.07.28 11:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (VBoxNetFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (Synth3dVsc)
DRV - File not found [File_System | On_Demand | Stopped] -- -- (StarOpen)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\user\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (akuzpcec)
DRV - [2013.01.20 15:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012.12.21 13:54:00 | 000,014,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv)
DRV - [2012.12.21 13:53:58 | 000,009,160 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2012.12.16 12:25:16 | 000,157,776 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2012.11.13 21:53:00 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Programme\Razer\Razer Game Booster\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - [2012.09.28 20:17:38 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012.09.28 20:16:08 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011.05.18 07:09:04 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2011.05.13 17:57:42 | 000,025,656 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hpdskflt.sys -- (hpdskflt)
DRV - [2011.05.13 17:57:20 | 000,035,896 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2011.04.21 14:14:45 | 000,004,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nocashio.sys -- (nocashio)
DRV - [2010.11.20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010.11.20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.07.22 22:01:00 | 009,791,072 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.07.20 03:39:20 | 000,116,136 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\jmcr.sys -- (JMCR)
DRV - [2009.06.25 23:55:12 | 000,066,080 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2009.03.18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory =
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = MSN Schweiz : Hotmail, Outlook, Skype download, Unterhaltung, Nachrichten, Sport, Lifestyle, Auto und mehr bei MSN CH
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-ch
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 61 15 EB A8 42 FC CB 01 [binary data]
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?FORM=UP21DF&PC=UP21&dt=031913&q={searchTerms}&src=IE-SearchBox
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\SearchScopes\{A24B23B3-6F36-4D6A-B21E-45D059F25D50}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYCH&apn_uid=2180B476-059B-4960-9567-F78D405B7FD8&apn_sauid=B98193CC-0BA5-4D6D-9988-1868E1C4BF38
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "DVDVideoSoftTB Customized Web Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.claro-search.com/?affID=114508&tt=4212_3&babsrc=HP_clro&mntrId=ec3baacd000000000000002100a83bd4"
FF - prefs.js..extensions.enabledAddons: helperbar@helperbar.com:1.0
FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.1.3
FF - prefs.js..extensions.enabledAddons: ffox@bandoo.com:5.1
FF - prefs.js..extensions.enabledAddons: ffxtlbr@Facemoods.com:1.2.1
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.4
FF - prefs.js..extensions.enabledAddons: {51a86bb3-6602-4c85-92a5-130ee4864f13}:3.6.0.10
FF - prefs.js..extensions.enabledAddons: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.5.0.12
FF - prefs.js..extensions.enabledAddons: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledAddons: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledAddons: {64ead72b-ffd4-4e01-aa3a-4c71665d73e4}:3.9.0.3
FF - prefs.js..extensions.enabledAddons: {90b49673-5506-483e-b92b-ca0265bd9ca8}:3.9.0.3
FF - prefs.js..extensions.enabledAddons: {40c3cc16-7269-4b32-9531-17f2950fb06f}:3.9.0.3
FF - prefs.js..extensions.enabledAddons: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.96
FF - prefs.js..extensions.enabledAddons: {3e9a3920-1b27-11da-8cd6-0800200c9a66}:3.6.3
FF - prefs.js..extensions.enabledAddons: {26647ca4-a2a7-4eac-8a72-761aa9141de7}:3.10.0.1
FF - prefs.js..extensions.enabledAddons: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.10.0.1
FF - prefs.js..extensions.enabledAddons: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}:2.0
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..browser.startup.homepage: "hxxp://home.sweetim.com/?crg=3.1010000.10001&barid={F1294482-9607-4144-92A5-7226087A4A2A}"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Softonic)"
FF - prefs.js..browser.startup.homepage: "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=13&cc="
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: F:\Program Files\AdobeReader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@eximion.com/KalydoPlayer: C:\Users\user\AppData\Roaming\Kalydo\KalydoPlayer\bin\npkalydo.dll (Eximion B.V.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\user\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\user\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\crossriderapp498@crossrider.com: C:\Users\user\AppData\Local\RewardsArcade\498\Firefox [2012.03.25 16:14:33 | 000,000,000 | ---D | M]
[2011.12.03 19:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\mozilla\Extensions
[2013.03.19 19:54:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\cev9a7zx.default\extensions
[2013.01.04 16:52:34 | 000,000,000 | ---D | M] (Wajam) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\cev9a7zx.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}
[2013.02.24 22:06:37 | 000,000,000 | ---D | M] (Claro Toolbar) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\cev9a7zx.default\extensions\ffxtlbr@claro.com
[2012.10.24 20:11:48 | 000,054,399 | ---- | M] () (No name found) -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\extensions\pricepeep@getpricepeep.com.xpi
[2012.10.13 18:27:00 | 000,037,914 | ---- | M] () (No name found) -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
[2013.02.23 19:21:04 | 000,002,308 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\askcom.xml
[2012.10.14 00:00:11 | 000,002,546 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\browsemngr.xml
[2013.02.24 22:06:54 | 000,001,300 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\claro.xml
[2011.07.24 14:30:04 | 000,000,931 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\conduit.xml
[2013.02.01 17:02:10 | 000,001,294 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\delta.xml
[2012.03.18 17:30:30 | 000,002,412 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\Linkury Smartbar Search.xml
[2011.07.23 20:05:08 | 000,002,501 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\SearchResults.xml
[2011.12.03 19:06:09 | 000,002,519 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\Search_Results.xml
[2012.04.26 16:25:51 | 000,002,060 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\softonic.xml
[2012.09.27 19:47:52 | 000,003,993 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\cev9a7zx.default\searchplugins\sweetim.xml
O1 HOSTS File: ([2013.03.19 20:23:09 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (File Bulldog Toolbar) - {1393c215-0520-410e-ab29-3badab478ec4} - C:\Programme\filebulldogtb\filebulldogDx.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programme\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (File Bulldog Toolbar) - {1393c215-0520-410e-ab29-3badab478ec4} - C:\Programme\filebulldogtb\filebulldogDx.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [EaseUS EPM tray] C:\Programme\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [File Bulldog Anti-phishing Domain Advisor] C:\ProgramData\File Bulldog Anti-phishing Domain Advisor\filebulldog_antiphishing.exe (blekko)
O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000..\Run: [Akamai NetSession Interface] C:\Users\user\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - F:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3523815195-3484323984-766912794-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.17.2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 85.119.136.140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77D5C26F-38A8-48EE-AA8F-CB479292E4BA}: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 85.119.136.140
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.19 21:39:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013.03.19 21:39:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013.03.19 21:39:29 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2013.03.19 21:27:40 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Skype
[2013.03.19 20:28:25 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.03.19 20:23:15 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.03.19 20:21:00 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\temp
[2013.03.19 20:11:02 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.03.19 20:11:02 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.03.19 20:11:02 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.03.19 20:10:58 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013.03.19 20:10:52 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.03.19 20:10:37 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.03.17 20:56:13 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\SumRando
[2013.03.17 20:56:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SumRando
[2013.03.17 20:55:05 | 000,000,000 | ---D | C] -- C:\Program Files\SumRando
[2013.03.17 20:50:20 | 000,000,000 | ---D | C] -- C:\toolbarImages
[2013.03.17 19:13:41 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\AVG
[2013.03.17 19:12:31 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG
[2013.03.17 19:12:28 | 000,000,000 | -HSD | C] -- C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
[2013.03.17 16:34:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013.03.11 20:34:48 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\DealPly
[2013.03.10 22:40:39 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\AVG2013
[2013.03.10 22:39:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013.03.10 22:39:24 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2013.03.10 22:39:24 | 000,000,000 | ---D | C] -- C:\$AVG
[2013.03.10 22:38:44 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2013.03.10 22:36:14 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\MFAData
[2013.03.10 22:36:14 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2013.03.10 22:36:14 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Avg2013
[2013.03.10 20:29:28 | 000,000,000 | ---D | C] -- C:\Windows\Repair
[2013.03.10 19:46:30 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2013.03.07 19:14:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Logs
[2013.03.05 22:33:18 | 000,000,000 | ---D | C] -- C:\ProgramData\filebulldogtb
[2013.03.04 21:17:08 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\.minecraft
[2013.03.01 19:09:53 | 000,000,000 | ---D | C] -- C:\Windows\System32\Neuer Ordner
[2013.02.28 19:20:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.2
[2013.02.28 19:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\Cheat Engine 6.2
[2013.02.28 19:19:45 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\filebulldogtb
[2013.02.28 19:19:44 | 000,000,000 | ---D | C] -- C:\ProgramData\File Bulldog Anti-phishing Domain Advisor
[2013.02.28 19:19:26 | 000,000,000 | ---D | C] -- C:\Program Files\filebulldogtb
[2013.02.28 19:14:47 | 000,000,000 | ---D | C] -- C:\Program Files\DragonCityBot
[2013.02.27 19:15:28 | 000,000,000 | ---D | C] -- C:\Windows\de
[2013.02.27 19:06:54 | 000,000,000 | R--D | C] -- C:\Users\user\SkyDrive
[2013.02.27 19:06:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SkyDrive
[2013.02.27 19:06:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft SkyDrive
[2013.02.27 14:05:44 | 000,000,000 | ---D | C] -- C:\Program Files\alaplaya
[2013.02.27 13:42:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Akamai
[2013.02.26 22:13:08 | 000,000,000 | ---D | C] -- C:\Users\user\tre
[2013.02.24 00:45:25 | 000,000,000 | ---D | C] -- C:\Program Files\RAR Password Unlocker
[2013.02.21 23:46:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Systweak
[2013.02.21 19:47:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
[2013.02.21 19:06:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
[2013.02.21 19:06:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\TechSmith Shared
[2013.02.21 19:05:21 | 000,000,000 | ---D | C] -- C:\Program Files\TechSmith
[2013.02.21 00:57:23 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Solveig Multimedia
[2013.02.21 00:55:30 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\HyperCam3
[2013.02.19 22:08:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2013.02.19 01:04:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Software
[16 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.03.19 22:29:07 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.19 22:25:41 | 000,020,704 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.19 22:25:41 | 000,020,704 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.19 22:19:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.19 22:19:26 | 2390,114,304 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.19 21:43:50 | 000,289,472 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.03.19 21:39:33 | 000,002,505 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2013.03.19 21:36:01 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3523815195-3484323984-766912794-1000UA.job
[2013.03.19 21:36:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3523815195-3484323984-766912794-1000Core.job
[2013.03.19 21:23:47 | 000,362,029 | ---- | M] () -- C:\Windows\System32\sqlite3.dll
[2013.03.19 20:23:09 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.03.18 22:26:07 | 050,069,504 | ---- | M] () -- C:\Windows\System32\RBK9DEC.bak
[2013.03.18 22:26:07 | 018,087,936 | ---- | M] () -- C:\Windows\System32\RBK9DEF.bak
[2013.03.18 22:26:07 | 000,524,288 | ---- | M] () -- C:\Windows\System32\RBK9DF4.bak
[2013.03.18 22:26:07 | 000,262,144 | -HS- | M] () -- C:\Windows\System32\RBK9E04.bak
[2013.03.18 22:26:07 | 000,262,144 | -HS- | M] () -- C:\Windows\System32\RBK9DFF.bak
[2013.03.18 22:26:07 | 000,262,144 | ---- | M] () -- C:\Windows\System32\RBK9DFC.bak
[2013.03.18 22:26:07 | 000,262,144 | ---- | M] () -- C:\Windows\System32\RBK9DF7.bak
[2013.03.18 22:25:48 | 004,718,592 | -H-- | M] () -- C:\Windows\System32\RBK9E0C.bak
[2013.03.18 22:25:48 | 004,194,304 | -HS- | M] () -- C:\Windows\System32\RBK9E07.bak
[2013.03.18 17:22:01 | 001,622,772 | ---- | M] () -- C:\Users\user\Desktop\x7.rar
[2013.03.18 17:21:48 | 000,648,112 | ---- | M] () -- C:\Users\user\Desktop\x7 Loader v1.0.0.zip
[2013.03.17 20:11:16 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2013.03.09 18:42:10 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for user.job
[2013.03.03 03:24:33 | 001,959,131 | ---- | M] () -- C:\main.wma
[2013.03.03 02:48:43 | 000,062,183 | ---- | M] () -- C:\xluiscolx.gif
[2013.02.27 13:59:41 | 000,008,627 | ---- | M] () -- C:\Windows\System32\PAV_FOG.OPC
[2013.02.22 00:38:37 | 000,007,602 | ---- | M] () -- C:\Users\user\AppData\Local\resmon.resmoncfg
[2013.02.21 00:57:24 | 000,005,632 | ---- | M] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.02.21 00:21:36 | 000,094,779 | ---- | M] () -- C:\Users\user\Documents\Unbenannt.wma
[2013.02.20 13:51:22 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013.02.20 13:28:09 | 003,124,964 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.02.20 13:28:09 | 001,385,526 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.02.20 13:28:09 | 000,924,562 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.02.20 13:28:09 | 000,820,910 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.02.18 01:12:03 | 000,001,506 | ---- | M] () -- C:\Windows\Sandboxie.ini
[16 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.03.19 21:43:24 | 000,289,472 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.03.19 21:39:33 | 000,002,505 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2013.03.19 21:23:47 | 000,362,029 | ---- | C] () -- C:\Windows\System32\sqlite3.dll
[2013.03.19 20:11:02 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.03.19 20:11:02 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.03.19 20:11:02 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.03.19 20:11:02 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.03.19 20:11:02 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.03.17 21:56:16 | 001,622,772 | ---- | C] () -- C:\Users\user\Desktop\x7.rar
[2013.03.17 21:56:13 | 000,648,112 | ---- | C] () -- C:\Users\user\Desktop\x7 Loader v1.0.0.zip
[2013.03.17 20:11:16 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2013.03.03 22:22:31 | 000,062,183 | ---- | C] () -- C:\xluiscolx.gif
[2013.03.03 22:22:30 | 001,959,131 | ---- | C] () -- C:\main.wma
[2013.02.27 19:14:40 | 000,001,251 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2013.02.27 19:13:55 | 000,001,320 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2013.02.27 19:06:54 | 000,002,172 | ---- | C] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
[2013.02.21 00:21:36 | 000,094,779 | ---- | C] () -- C:\Users\user\Documents\Unbenannt.wma
[2013.02.19 23:23:28 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013.02.19 23:22:46 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013.02.19 22:09:06 | 000,001,912 | ---- | C] () -- C:\Windows\epplauncher.mif
[2013.02.19 22:08:21 | 000,002,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013.02.03 23:07:15 | 002,468,520 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2013.02.03 23:07:15 | 000,087,112 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2013.02.03 23:07:15 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2013.02.03 23:07:15 | 000,014,920 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2013.02.03 23:07:15 | 000,009,160 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2012.08.23 17:42:56 | 000,828,671 | ---- | C] () -- C:\Users\user\AppData\Local\Tempmusic.ogg
[2012.08.22 13:45:57 | 000,001,506 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2012.03.05 18:32:59 | 000,000,833 | ---- | C] () -- C:\Users\user\.recently-used.xbel
[2012.02.26 17:41:54 | 000,000,023 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011.09.15 01:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin
[2011.08.22 20:31:19 | 000,005,632 | ---- | C] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.18 17:10:31 | 000,001,087 | ---- | C] () -- C:\Users\user\Dokumente - Verknüpfung.lnk
[2011.07.08 19:48:57 | 000,273,148 | ---- | C] () -- C:\Windows\Bergbau0.8.exe
[2011.06.20 23:54:54 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.06.20 23:52:24 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.04.26 21:10:37 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.04.21 14:14:45 | 000,004,096 | ---- | C] () -- C:\Windows\System32\drivers\nocashio.sys
[2011.04.15 16:36:25 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2011.04.15 16:10:42 | 000,007,602 | ---- | C] () -- C:\Users\user\AppData\Local\resmon.resmoncfg
[2011.04.15 15:31:09 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.03.17 16:28:21 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\AVG2013
[2013.02.22 11:31:53 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Bandoo
[2013.02.13 10:57:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\dll-files.com
[2013.02.22 11:28:42 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Systweak
[2013.03.13 18:38:05 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\.minecraft
[2012.09.06 17:07:52 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\.Nitrous
[2011.09.08 21:06:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ACASystems
[2012.09.22 17:30:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Aeria Games & Entertainment
[2012.11.02 22:43:41 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ArmA II Launcher
[2012.11.12 21:04:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Audacity
[2013.01.30 23:00:47 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Auslogics
[2013.03.17 19:13:41 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\AVG
[2013.03.10 22:40:39 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\AVG2013
[2011.07.25 20:03:48 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\avidemux
[2013.01.27 16:17:16 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Azureus
[2012.03.22 18:15:59 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Babylon
[2011.06.22 20:25:29 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Bandoo
[2012.08.12 13:47:12 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\bin
[2013.02.27 13:35:44 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\BitTorrent
[2011.04.16 23:54:09 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Canneverbe Limited
[2011.09.03 12:33:27 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Charles
[2013.01.27 16:17:16 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DAEMON Tools Lite
[2011.09.17 17:05:11 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DAEMON Tools Pro
[2013.03.11 20:34:48 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DealPly
[2012.12.24 00:35:11 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\dll-files.com
[2011.08.13 17:34:38 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DVDVideoSoft
[2011.08.13 17:32:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.04.15 15:27:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ESET
[2012.03.22 18:18:37 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\eType
[2011.04.26 21:14:10 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FireShot
[2011.07.22 20:08:03 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FOG Downloader
[2011.05.15 22:05:18 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\GetRightToGo
[2012.03.05 18:34:52 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\gtk-2.0
[2012.01.10 21:28:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Kalydo
[2013.02.02 14:58:05 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\MessengerDiscovery 2
[2011.08.01 18:06:23 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\minecraft
[2011.07.25 22:44:35 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Minecraft Server 1.5
[2013.01.11 23:21:01 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\MTE
[2013.02.25 22:21:51 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Notepad++
[2013.01.15 16:43:45 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenCandy
[2012.03.22 18:22:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PerformerSoft
[2012.11.02 22:37:52 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Play withSIX
[2011.04.17 22:48:05 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ProtectDISC
[2011.07.01 22:42:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\resources
[2011.07.01 22:42:17 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\saves
[2013.02.21 01:04:55 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Solveig Multimedia
[2013.02.27 13:35:41 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\stats
[2013.03.19 19:55:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\systweak
[2012.10.22 16:46:18 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TechSmith
[2012.08.12 13:47:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TS3Client
[2013.03.10 22:39:53 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TuneUp Software
[2013.01.04 16:53:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TuneUpMedia
[2013.02.27 13:35:41 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\uTorrent
[2011.07.19 21:26:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012.08.20 18:17:39 | 000,000,000 | ---D | M](C:\Windows\System32\????sers) -- C:\Windows\System32\༸sers
[2012.08.20 18:17:39 | 000,000,000 | ---D | C](C:\Windows\System32\????sers) -- C:\Windows\System32\༸sers
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:373E1720
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:07BF512B
< End of report > --- --- --- |